Diffusion-Based Adversarial Purification for Speaker Verification

被引:0
|
作者
Bai, Yibo [1 ]
Zhang, Xiao-Lei [2 ,3 ,4 ]
Li, Xuelong [3 ]
机构
[1] Univ Hong Kong, Dept Elect & Elect Engn, Hong Kong, Peoples R China
[2] Northwestern Polytech Univ, Sch Marine Sci & Technol, Xian 710072, Peoples R China
[3] China Telecom Corp Ltd, Inst Artificial Intelligence TeleAI, Beijing 100033, Peoples R China
[4] Northwestern Polytech Univ, Res & Dev Inst, Shenzhen 518063, Peoples R China
关键词
Purification; Perturbation methods; Noise reduction; Acoustics; Training; Security; Diffusion processes; Adversarial defense; diffusion model; speaker verification;
D O I
10.1109/LSP.2024.3418715
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Recently, automatic speaker verification (ASV) based on deep learning is easily contaminated by adversarial attacks, which is a new type of attack that injects imperceptible perturbations to audio signals so as to make ASV produce wrong decisions. This poses a significant threat to the security and reliability of ASV systems. To address this issue, we propose a Diffusion-Based Adversarial Purification (DAP) method that enhances the robustness of ASV systems against such adversarial attacks. Our method leverages a conditional denoising diffusion probabilistic model to effectively purify the adversarial examples and mitigate the impact of perturbations. DAP first introduces controlled noise into adversarial examples, and then performs a reverse denoising process to reconstruct clean audio. Experimental results demonstrate the efficacy of the proposed DAP in enhancing the security of ASV and meanwhile minimizing the distortion of the purified audio signals.
引用
收藏
页码:2300 / 2304
页数:5
相关论文
共 50 条
  • [1] Robust Evaluation of Diffusion-Based Adversarial Purification
    Lee, Minjong
    Kim, Dongwoo
    2023 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION, ICCV, 2023, : 134 - 144
  • [2] DiffAttack: Evasion Attacks Against Diffusion-Based Adversarial Purification
    Kang, Mintong
    Song, Dawn
    Li, Bo
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 36 (NEURIPS 2023), 2023,
  • [3] Iterative Window Mean Filter: Thwarting Diffusion-Based Adversarial Purification
    Wang, Hanrui
    Sun, Ruoxi
    Chen, Cunjian
    Xue, Minhui
    Soon, Lay-Ki
    Wang, Shuo
    Jin, Zhe
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2025, 22 (02) : 1827 - 1844
  • [4] From Deconstruction to Reconstruction: A Plug-In Module for Diffusion-Based Purification of Adversarial Examples
    Bao, Erjin
    Chang, Ching-Chun
    Nguyen, Huy H.
    Echizen, Isao
    DIGITAL FORENSICS AND WATERMARKING, IWDW 2023, 2024, 14511 : 48 - 62
  • [5] ADVERSARIAL SPEAKER VERIFICATION
    Meng, Zhong
    Zhao, Yong
    Li, Jinyu
    Gong, Yifan
    2019 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP), 2019, : 6216 - 6220
  • [6] LatentColorization: Latent Diffusion-Based Speaker Video Colorization
    Ward, Rory
    Bigioi, Dan
    Basak, Shubhajit
    Breslin, John G.
    Corcoran, Peter
    IEEE ACCESS, 2024, 12 : 81105 - 81121
  • [7] Self-supervised learning with diffusion-based multichannel speech enhancement for speaker verification under noisy conditions
    Dowerah, Sandipana
    Kulkarni, Ajinkya
    Serizel, Romain
    Jouvet, Denis
    INTERSPEECH 2023, 2023, : 3849 - 3853
  • [8] DIFFender: Diffusion-Based Adversarial Defense Against Patch Attacks
    Kang, Caixin
    Dong, Yinpeng
    Wang, Zhengyi
    Ruan, Shouwei
    Chen, Yubo
    Su, Hang
    Wei, Xingxing
    COMPUTER VISION - ECCV 2024, PT LII, 2025, 15110 : 130 - 147
  • [9] Diffusion-Based Adversarial Sample Generation for Improved Stealthiness and Controllability
    Xue, Haotian
    Araujo, Alexandre
    Hu, Bin
    Chen, Yongxin
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 36 (NEURIPS 2023), 2023,
  • [10] A Guided Diffusion-based Approach to Natural Adversarial Patch Generation
    He K.
    She J.-S.
    Zhang Z.-J.
    Chen J.
    Wang X.-X.
    Du R.-Y.
    Tien Tzu Hsueh Pao/Acta Electronica Sinica, 2024, 52 (02): : 564 - 573